Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Pidgin was pretty awesome, though its underlying library was so riddled with vulnerabilities…

I greatly enjoyed how with XMPP’s in-band registration you could do things like give each contact a unique XMPP address, only to be used with them. You could have unlimited (well, I never hit a limit) accounts, across a load of servers, proxies per account, unique OTR keys per account, etc.

I don’t think the UI has really been surpassed either, tbh. I really wish someone would do a modern rewrite of Pidgin in some memory safe language.



Responsibly disclosing security issues is paramount to software security. See https://pidgin.im/about/security/advisories/ for a full break down.

That said, the vulnerabilities in "libpurple" were way over hyped by someone who rightfully got kicked out of the security community. Most of those vulnerabilities were in fact in protocol implementations that are plug-ins to libpurple and not libpurple itself. I know it's a technicality, but hearing this blatant lie get repeated for over a decade is exhausting.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: